Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-502

MITRE ↗

Deserialization of Untrusted Data

1,189
CRITICAL
1,464
HIGH
360
MEDIUM
26
LOW
3,107 CVEs · Page 15/63
7.2
CVE-2026-8135

Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the Ex

7.2
CVE-2026-39434

Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.

7.2
CVE-2026-39471

Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.

7.2
CVE-2026-39472

Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.

7.2
CVE-2026-39481

Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.

7.2
CVE-2026-39498

Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.

7.2
CVE-2026-39499

Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.

7.2
CVE-2025-27511

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the G

7.2
CVE-2026-59521

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Inj

7.2
CVE-2026-65497

Administrator PHP Object Injection in Complianz <= 7.5.0 versions.

7.2
CVE-2026-65549

Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.

7.2
CVE-2026-27380

Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.

7.2
CVE-2026-66256

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects A

7.2
CVE-2026-66620

Editor PHP Object Injection in OptionTree <= 2.7.3 versions.

7.2
CVE-2026-78276

Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.

7.2
CVE-2026-14558

The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises use

7.2
CVE-2026-81757

Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.

7.1
CVE-2026-32590

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores interm

7.1
CVE-2026-9291

Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remot

7.1
CVE-2026-45134

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and

7.1
CVE-2026-55153

mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool.

7.1
CVE-2025-7639

The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to ta

7.0
CVE-2026-7818

Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe

6.8
CVE-2026-23946

Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions

6.8
CVE-2026-28277

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async,

6.8
CVE-2026-48775

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async,

6.7
CVE-2026-4266

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to

6.7
CVE-2026-53914

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

6.6
CVE-2026-27794

LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execu

6.6
CVE-2026-48917

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.

6.6
CVE-2026-48919

Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.

6.6
CVE-2026-7566

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up t

6.6
CVE-2026-12115

The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Objec

6.6
CVE-2026-16062

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co

6.6
CVE-2026-68756

A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

6.6
CVE-2026-10035

The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and

6.6
CVE-2026-59275

A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — fu

6.6
CVE-2026-76547

The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when impor

6.5
CVE-2025-70559

pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The libra

6.5
CVE-2026-1235

The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthentic

6.5
CVE-2026-1542

The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated

6.5
CVE-2026-1286

CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an

6.5
CVE-2026-42521

Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructor

6.5
CVE-2026-1184

GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18

6.5
CVE-2026-27410

Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.

6.5
CVE-2026-56304

picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to cr

6.5
CVE-2026-62912

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a netw

6.5
CVE-2026-63516

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over

6.4
CVE-2026-34993

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJ

6.4
CVE-2026-24220

NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an uns

Frequently Asked Questions

What is CWE-502?

CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-502?

There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.

How can I protect against CWE-502 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.

Detect CWE-502 Vulnerabilities

CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.

Get Started